SSL Cipher Checker
See exactly which cipher suites a server accepts. Our server tries common TLS 1.2 suites and all three TLS 1.3 suites one at a time, each in its own handshake, and rates them: strong (ECDHE with AES-GCM or ChaCha20-Poly1305), acceptable (DHE with GCM), weak (CBC mode or static RSA key exchange without forward secrecy) and insecure (3DES). Suites our OpenSSL cannot offer are marked as not tested.
- Encrypted connection
- No sign-up
- Free to use
How to use SSL Cipher Checker
- Enter a domain.
- Click Check ciphers.
- Disable insecure and weak suites.
- Prefer ECDHE with GCM or ChaCha20.
SSL Cipher Checker features
One suite per handshake
Exact accept/refuse results.
Strength rating
Strong, ok, weak, insecure.
TLS 1.3 suites
All three tested.
Grade
Penalises weak and insecure suites.
Not-tested marker
No guessing.
Parallel
Results in seconds.
When to use SSL Cipher Checker
- Server hardening.
- Compliance evidence.
- Load balancer and CDN reviews.
- Comparing hosting providers.
SSL Cipher Checker FAQ
What is forward secrecy?
With ECDHE or DHE key exchange, recorded traffic cannot be decrypted later even if the server key is stolen.
Why are CBC suites weak?
CBC mode has a history of padding-oracle attacks; AEAD modes like GCM are safer.
Is every possible suite tested?
No – the most widely used suites. That covers what real clients negotiate.
Why is 3DES insecure?
Its 64-bit block size makes it vulnerable to the Sweet32 attack.
Fewer, stronger suites
Modern clients all support ECDHE with AES-GCM or ChaCha20-Poly1305. Removing older suites rarely affects real users.
How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.
Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.
Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.
Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.
Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.